NetDragon is a purpose-built botnet malware first observed in October 2024 that targets Feiniu fnOS network-attached storage (NAS) devices. It compromises exposed fnOS services and leverages undisclosed vulnerabilities in the platform to implant malicious code, deploy an HTTP backdoor, and install a modular malware stack consisting of a loader and a DDoS component. On infected devices, it enables remote arbitrary command execution and enrolls the NAS into a botnet used for large-scale denial-of-service attacks.
The malware uses strong persistence and defense evasion. Reported mechanisms include dual persistence through a user-space systemd service and a kernel module, allowing it to survive reboots even if one component is removed. It tampers with the hosts file to redirect the official update domain to 0.0.0.0, preventing security updates and system upgrades. Additional anti-analysis and concealment behaviors include dynamic key packing for obfuscation, deletion of system logs, manipulation of process lists, and disruption of network monitoring tools during active attacks.
A notable destructive behavior is deletion of the file rsa_private_key.pem on infected devices, which was assessed as creating a severe and potentially permanent data security risk. Specific artifacts directly associated with the malware include the malicious kernel module async_memcpys.ko, the malicious user-mode service dockers.service, malware-injected nftables and iptables firewall rules, and an HTTP backdoor associated with port 57199.
QiAnXin / Qi An Xin X Lab reported on the campaign and assessed roughly 1,500 infected devices by the end of January 2026; another cited report stated more than 1,143 bots were online by late January 2026. Victims were concentrated primarily in China, with additional infections reported in the United States and Singapore, spanning sectors including software services and public administration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware targeting Feiniu fnOS NAS devices, primarily affecting Chinese home users and SMBs.
DDoS botnet active since late 2024; noted infecting NAS devices running fnOS.
Botnet malware targeting Feiniu fnOS NAS devices by exploiting undisclosed vulnerabilities/exposed services to install a modular loader + DDoS component and an HTTP backdoor, enabling remote command execution, persistence via systemd services and kernel modules, and use of infected devices for large-scale DDoS attacks. It also blocks updates by hijacking the update domain in the hosts file, deletes logs, manipulates process lists, disrupts monitoring tools, and was observed deleting rsa_private_key.pem on devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.